
Dr Andrea Cullen at CAPSLOCK explains how to widen the talent pool in cyber-security with on-demand contractors
The UK cyber-security sector continues to face a significant challenge filling roles, with the Government estimating that 51% of UK businesses have a basic cyber-security skills gap.
The shortfall of cyber-security workers means that many teams are stretched and at risk of burnout, potentially leading to higher attrition rates and making the skills gap even wider. With the risk landscape changing daily and the scale and frequency of cyber-attacks escalating, cyber-security leaders are under immense pressure to shore up the defences of their organisations.
So, what are they to do in such a Catch-22 moment?
The clear answer to this question would be: hire, hire, hire. However, as mentioned, it’s already difficult to fill cyber-security roles. Hiring teams don’t always understand what skills are needed and can get bogged down in asking for specific certifications rather than looking for the most useful skills and experience.
But finding the right talent can also be challenging because of a shortage of skilled talent. Added to that, cyber-security teams are often underfunded functions, with 57% of UK businesses lacking the resources to fund expert cyber-security advice. This means that adding to their permanent headcount can become a battle with the board.
There are two main solutions I see playing out in the short and long term.
1.Bridging skill gap, quickly
An immediate response to the problem that CSOs and CISOs can take is to deploy certified cyber-security contractors to fill team vacancies temporarily. This helps alleviate immediate pressure on the teams by adding headcount quickly – whether because they’re struggling to hire permanent talent, are navigating a hiring cycle freeze or need additional support on specific projects.
By deploying contractors, cyber-security leaders don’t have the financial pressure of making a permanent hire but instead, sign up for a fixed daily rate. With this also come savings on traditional permanent hire costs, including recruitment fees, national insurance, pensionsand holiday pay.
Further, they can select contractors based on skillsets to fill the exact criteria. From entry to senior levels, they can hire contractors across varied specialist and generalist roles, including governance, risk and compliance, vulnerability management, and SOC analysis and threat intelligence. This can lower the financial burden on the organisation, particularly during times of economic uncertainty and ensure that specific skills and expertise are available.
Not only can hiring cyber-security professionals contractually solve an immediate shortage, it can also set up a diverse talent pool for future hires. By welcoming contractors, organisations can show off the company culture, values and practices, creating a talent network that already knows the company well.
At the same time, they benefit from working with an individual for several months at a time, knowing whether they could be a good long-term fit. Indeed, they hire those contracted in permanently, introducing a new team member who can hit the ground running and provide real value to the existing team from day one.
2.Looking internally for cyber-security talent
Contracting cyber-security professionals is more than just filling the all-important skills gap. It opens the organisation up to a talent pool of diverse skills and provides a valuable opportunity for contractors to gain on-the-job cyber-security experience.
However, another avenue that organisations can take is to look at their own, internal talent and whether there are opportunities to reskill existing employees in cyber-security.
Reskilling existing employees is a great strategy for businesses navigating the cyber-skills gap. By finding individuals from the existing workforce rather than searching a restricted talent pool, organisations have a great foundation of business knowledge that can be reskilled in specific cyber-security disciplines. Not only that but bringing them in from different functions and career backgrounds means they will also benefit from diversity of thinking and experience
Solving the wider issue of improving diversity
This touches on a wider issue that the cyber-security sector faces. As someone who has worked in UK tech for over 30 years, including many years in cyber-education, I’m very familiar with the root cause of this huge skills deficit: diversity.
I’ve seen first-hand how challenging it is to enter the profession, even at entry-level, with limited or no experience. Despite having great transferable “soft” or “impact” skills such as problem-solving, people without the right technical or educational background are often prevented from getting a valuable first step in the door of cyber-teams.
This has created a diversity problem, with only 36% of cyber-security professionals being female, 15% ethnic minorities and 16.5% eligible for free school meals. Without role models to encourage those from different backgrounds, the traditional demographic of middle-class white males will remain, and cyber-security leaders risk losing out on the valuable insights and skills a diverse team can bring.
By creating more opportunities for nurturing talent within professional organisations, they can help break down barriers and widen opportunities within cyber-security. This can pave the way to improving the skills gap in the long term by creating a larger cyber-security talent pool.
Turning shortages into opportunities
Solving the cyber-skills gap is not an overnight job. So, for CISOs facing shortages, they can look to contractors to expand and diversify their team quickly with skilled workers or choose to retrain existing employees from other areas of the business wanting career changers.
This is a lesson for the wider sector: such initiatives are opportunities to look outside of traditional routes for talent development to create a community of skilled professionals who have experienced the real cyber-security workplace and are prepared for the realities of working in cyber-security.
Cyber-security leaders have a responsibility to pave the way for more diverse talent for a resilient and adaptable workforce. By breaking down barriers to entering the profession, they can lay the foundation for a stronger sector which is up to taking on future challenges.
Dr Andrea Cullen is CEO and Co-Founder of CAPSLOCK
Main image courtesy of iSTockPhoto.com and SeventyFour
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543